Sample Content

Online Sample Chapter

Downloadable Sample Chapter

Table of Contents

Foreword.

Acknowledgments.

About the Author.

Introduction.

1. Responding to Attacks.

Incident-Response Nightmare. Day 1: Unauthorized Access. Day 2: Problem Fixed. Day 3: Security Is Breached Again. Days 4 to 7: Escalating the Incident. Day 8: Too Late to Gain Evidence. Day 9: Who Was the Bad Guy? Summary: Attacks from the Inside. Let's Not Go There… Focus on Prevention. Prepare for the Worst. React Quickly and Decisively. Follow Up. Checklist. Final Words.

2. Out-of-the-Box Security.

Deal with Security Later. Day 1: False Sense of Security. Two Years Later: Noticed the Attack. + Two Weeks: The Hacker's Back. + Three Weeks: Fixing Security. The Saga Continues: The Network Remains at Risk. Summary: Would You Hire This ISP? Let's Not Go There… Know Your Risks. Avoid Out-of-the-Box Installations. Test Your Network. Know the People Who Know Your Data. Assign or Acquire Adequate Funding for Security. Don't Export Read/Write Permissions to the World. Remove Old Accounts. Test Passwords. Apply Security Patches. Follow Policies and Procedures. Work with Experts. Use Training. Checklist. Final Words.

3. Executive Support.

Executive Commitment. Day 1: Unsecured Systems. A Year Later: Unauthorized Access Continues. Summary: Take an Active Approach. Let's Not Go There… Commit to Security from the Top Down. Don't Delegate Security. Keep Levels of Management to a Minimum. Report Back to Executive Management. Set Security as a Corporate Goal. Provide or Take Training as Required. Make Sure That All Managers Understand Security. Communicate to Management Clearly. Checklist. Final Words.

Unsafe Network. In the Beginning: Bypassing the Corporate Network. Day 1: Collecting Evidence. Day 2: System Administrators Versus the Security Team. Who Owns Security. Transferring Responsibility. Summary: Security Is the Casualty of War. Let's Not Go There… Put Someone in Charge of Policies and Procedures. Delineate Cross-Organizational Security Support. Don't Wait for Miracles. Question Processes. Know When to Cry “Uncle”. Be Responsible. Checklist. Final Words.

9. Outsourcing Security.

Forget Security? Day 1: Taking a Look at Security Controls. Day 2: Network Connections. Amazing Security Mistakes. Untrained and Inexperienced Support. Days 3 and 4: Does Management Understand? Summary: Outsourced Systems Must Be Secured. Let's Not Go There… Conduct Security Assessments. Do It Right. Do It Regularly. Fix the Problems You Find. Don't Use the Sink-or-Swim Approach. Checklist. Final Words.

10. Unsecure Email.

Email or See Mail? Personal Data Accessed. Summary: You Have the Right to Waive Your Right to Privacy. Let's Not Go There... Use Encryption! Encourage Your Company to Encrypt. Add Encryption to Your Security Budget. Watch for Other Email Hazards. Final Words.